CVE-2026-104890: Kunstmaan CMS: MediaBundle extension blacklist bypass allows authenticated administrators to upload executable PHP files leading to remote code execution

Published Oct 5, 2026
·
Updated

Kunstmaan CMS is an open source content management system based on the Symfony framework. Prior to 7.3.2, src/Kunstmaan/MediaBundle/Helper/File/FileHandler.php performs the blacklistedextensions check case-sensitively in FileHandler::getFilePath and lowercases the stored extension afterward. An authenticated backend user with media access can upload a mixed-case executable extension such as PHP that bypasses the check and is stored in the web-accessible media directory with an executable lowercase extension. The default blacklist also omits several server-executable extension types, allowing the same code-execution impact where the web server executes uploaded files. This issue is fixed in version 7.3.2.

Affected Software

1 affected component
Kunstmaan Kunstmaan CMS<7.3.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Kunstmaan CMS to a version that resolves this vulnerability.

    Fixed in 7.3.2

Event History

Oct 5, 2026
CVE Published
via MITRE·03:46 PM
Data Sourced
via MITRE·03:46 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated backend user with access to the media upload functionality can exploit it. Exploitation does not require user interaction.

2

Are installations using the default extension blacklist affected?

Yes. In addition to the case-sensitive blacklist bypass using mixed-case extensions such as PHP, the default blacklist omits some extension types that web servers may execute.

3

What conditions are required for remote code execution?

The uploaded file must be placed in the web-accessible media directory, and the web server must be configured to execute the uploaded extension type. A successful upload is stored with a lowercased extension.

4

What should teams do if they cannot upgrade immediately?

Restrict media upload access to only trusted backend users and ensure the web server does not execute scripts from the web-accessible media directory. Review the configured blacklist for executable extensions supported by the web server.

5

How can administrators determine whether their deployment is affected?

Deployments running versions prior to 7.3.2 are affected. Review uploaded media for executable files, including files whose original upload used mixed-case extensions, in the web-accessible media directory.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203